Race condition in ClamAV - #VU141304

 

Race condition in ClamAV - #VU141304

Published: August 7, 2026


Vulnerability identifier: #VU141304
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to replace source paths during quarantine move and remove actions.

The vulnerability exists due to race condition in FreeBSD quarantine move and remove actions when handling source paths. A local user can manipulate source paths to replace them during quarantine move and remove actions.

This issue applies on FreeBSD.


Affected software

ClamAV

Remediation

Install security update from vendor's website.

ClamAV - addressed in versions 1.4.6, 1.5.4

External References

Related Security Bulletins